Introducing Agent Bridge — a two-way link to your AI agents.See how it works

Security & Trust

Your data stays yours.
Full stop.

IntakeOS is built for enterprise teams sharing sensitive process intelligence. We treat that responsibility seriously - with architectural decisions, contractual commitments, and a compliance roadmap designed to give your security team every answer they need.

Secure server infrastructure in a data center, representing IntakeOS's enterprise-grade controls, encryption, and SOC 2 compliant data handling

SOC 2 Type II - Observation period

Audit engagement underway. Controls are being evaluated over time.

TLS 1.3 + AES-256 encryption

All data encrypted in transit and at rest.

Zero model training on your data

Contractual and architectural guarantee.

Data Privacy

We never train AI models
on your process data.

When your team describes a process to VARA, that information is used exclusively to conduct your intake and generate your report. It is never pooled, aggregated, or used to improve AI models - not ours, not our providers'.

This isn't a policy preference - it's a hard architectural and contractual constraint enforced at every layer of the stack. We operate our AI calls through provider agreements that explicitly prohibit training on API inputs. Your process intelligence is competitively sensitive; we treat it that way.

AI providers contractually prohibited from training on your inputs

No cross-tenant data sharing or model fine-tuning

Intake transcripts scoped to your organisation - never visible to other customers

You own your data. We are custodians, not owners.

Data deletion requests honoured within 30 days

What happens to your data

01

Intake conversation

VARA's questions and your team's answers are sent to an AI inference endpoint over TLS. The prompt is processed and discarded - never stored by the model provider.

02

Report generation

Your answers feed the deterministic scoring engine first. AI is then called to enrich explanations. The generated report is stored encrypted in your tenant's isolated data partition.

03

At rest

Reports, transcripts, and attachments live in AES-256 encrypted storage, scoped to your organisation. No IntakeOS employee can read your data without an approved access request logged in our audit trail.

04

On deletion

When you request deletion, data is purged from primary storage within 30 days and from backups within 90 days. You receive written confirmation.

Compliance Roadmap

Working toward SOC 2 Type II

We've engaged a registered audit firm and are actively building toward SOC 2 Type II certification. Here's where we stand and what's next.

Complete

Security controls documented

All security policies, access control procedures, change management, and incident response playbooks are written, reviewed, and version-controlled.

Complete

Controls implemented

Technical controls (encryption, RBAC, SSO, audit logging, MDM) are deployed across all production infrastructure and corporate devices.

In Progress

Observation period

We are currently in our formal observation window with our auditors to prove consistent adherence to our documented controls over time.

Need our security documentation now?

We can share our current security controls summary, data processing addendum (DPA), and sub-processor list under NDA. Enterprise customers receive these as part of the onboarding package.

Request documentation
Controls & Architecture

Security built into every layer

Defence-in-depth isn't a buzzword for us - it's how we architect every service. Here's what's in place today.

Encryption everywhere

  • TLS 1.3 for all data in transit - no unencrypted channels
  • AES-256 at rest for database rows, object storage, and backups
  • Secrets managed in a dedicated secrets vault, never in environment variables or source code
  • Database credentials rotated automatically on a fixed schedule

Access control

  • Role-based access control (RBAC) - Admin, Business User, and Staff roles with least-privilege defaults
  • Multi-tenant isolation: each organisation's data is logically separated with organisation-scoped queries enforced at the API layer
  • Internal staff access to production requires a tracked, time-limited access request
  • All admin actions are written to an immutable audit log with actor, action, timestamp, and IP

Infrastructure

  • Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA
  • Data residency in the United States; EU region available for enterprise contracts
  • Automated backups with point-in-time recovery, retained for 30 days
  • Separate production, staging, and development environments - no production data in dev or staging

Monitoring & detection

  • Centralised structured logging for every API request - response times, status codes, user context
  • Anomaly detection alerts for unusual access patterns or bulk data exports
  • Dependency vulnerability scanning on every build; critical CVEs trigger same-day patches
  • Penetration testing conducted annually by an independent third party

Incident response

  • Documented incident response plan with defined severity levels (P0–P3)
  • Security incidents affecting customer data disclosed within 72 hours of discovery
  • Dedicated security contact: security@intakeos.ai - monitored 24/7
  • Post-incident reviews published for P0 and P1 events

AI sub-processors

  • AI inference routed only to providers with enterprise data processing agreements in place
  • Agreements explicitly prohibit use of API inputs for model training or improvement
  • Sub-processor list maintained and shared on request; customers notified of additions 30 days in advance
  • AI calls include no PII in system prompts - process descriptions only, never employee names or contact data unless voluntarily provided
People & Process

Security starts with our team

Technical controls only go so far. We invest equally in making sure the humans operating the platform understand, own, and enforce our security posture.

Background checks

All employees and contractors with access to production systems undergo identity verification and background screening before their first day.

Security awareness training

Mandatory security training at onboarding, plus quarterly refreshers covering phishing, social engineering, and safe data handling.

Least-privilege access

No engineer has standing access to production data. Access is granted on request, scoped to the minimum required, time-limited, and fully logged.

Device security

Company-issued devices require full-disk encryption, MDM enrollment, and auto-lock. Personal devices are prohibited from accessing production systems.

Vendor & Supply Chain

Our sub-processors are held to the same standard

We review every third-party vendor before onboarding and require data processing agreements that mirror the commitments we make to you.

Vendor security reviews

Every sub-processor must complete a security questionnaire and demonstrate adequate controls before we integrate their service.

DPA coverage

All vendors processing personal or intake data sign a Data Processing Addendum that includes purpose limitations, data deletion requirements, and breach notification SLAs.

30-day sub-processor notice

We notify customers at least 30 days before adding a new sub-processor that will touch your data. You have the right to object.

Annual vendor re-review

Sub-processors are reviewed annually. Any vendor failing to maintain adequate security controls is offboarded.

Security and engineering team reviewing controls together
Colleagues discussing compliance requirements in an office
FAQ

Questions your security team will ask

We've answered the most common ones below. If you need anything else, email security@intakeos.ai.

Does IntakeOS use my intake data to train AI models?
No - never. Your intake transcripts and process descriptions are used solely to produce your reports. We operate under data processing agreements with our AI providers that explicitly prohibit training on API inputs. This is a contractual and architectural guarantee, not just a policy statement.
Where is my data stored?
Data is stored in the United States by default on enterprise-grade cloud infrastructure. For enterprise customers with data residency requirements, we offer EU-based storage. Speak to our team to configure this before onboarding.
Who inside IntakeOS can see my intake data?
Nobody has standing access to your data. Any IntakeOS employee who needs to access production data for support or debugging purposes must submit an access request, which is reviewed, time-limited, and logged in our audit trail. You can request a copy of access logs for your tenant at any time.
Are you GDPR compliant?
Yes. We act as a data processor for personal data your organisation submits. We provide a Data Processing Addendum (DPA) covering all GDPR obligations - lawful basis, data subject rights, breach notification (72-hour), sub-processor controls, and cross-border transfer mechanisms including Standard Contractual Clauses (SCCs) for EU customers.
What happens if there's a security breach?
We will notify affected customers within 72 hours of becoming aware of any breach involving their data. Our incident response plan includes immediate containment, forensic investigation, regulatory notification where required, and a post-incident review. Our security contact (security@intakeos.ai) is monitored 24/7.
Can I delete my data?
Yes. You can request deletion of your organisation's data at any time. Data is purged from primary storage within 30 days and from backups within 90 days. You receive written confirmation of the deletion. We do not retain data beyond what is required for legal obligations.
Do you conduct penetration testing?
Yes. We engage an independent third-party security firm to conduct penetration testing at least annually. Findings are remediated on a risk-prioritised schedule - critical and high findings are addressed within 14 days.
When will SOC 2 certification be complete?
We are currently in the observation period with our audit firm. We will update this page when the SOC 2 Type II audit is complete. In the meantime, we can share our current security controls documentation, DPA, and sub-processor list under NDA on request.

Have more questions?
Our team is ready.

We're happy to complete your vendor security questionnaire, provide our DPA, join a security review call, or connect you directly with our compliance lead.

We aim to respond to all security enquiries within one business day.